Privacy Policy

Flexible IT (“Flexible IT”, “we”, “us”, “our”) is committed to protecting your privacy while providing you with a positive experience on our website and in using our products and services.

This Privacy Policy (“Policy”) explains how and why we collect, use, and share personal information from our clients, website visitors, and the end users of our services. It applies to the Flexible IT website at flexibleit.com and to Flexible IT’s apps. In this Policy, “the App” means any Flexible IT application you use. 

The Policy also describes the choices available to you regarding access to, correction of, and deletion of your personal information. We recommend you read it in full.

 

HOW WE GATHER PERSONAL INFORMATION

We may collect personal information from or about you in a variety of ways.

Your organization provides it to us. You cannot sign up for a Flexible IT account yourself. We provision accounts for the employees and authorized end users of organizations that have a services agreement with us, and your organization gives us your details when it asks us to set your account up.

You provide it to us directly. When you sign in, submit a support ticket, attach a file, or contact us through our website.

We collect it automatically. As you use the App or visit our website.

We do not buy personal information from data brokers or enrichment vendors, and we do not receive it from advertising networks or social media platforms.

 

CATEGORIES OF PERSONAL INFORMATION WE COLLECT AND USE

In this Policy, “personal information” means any information relating to an identified or identifiable person that we process in connection with our website, the App, or our services.

Information provided to us

Category of personal data

Examples

Flexible IT uses this data to:

Contact and account information

Your name, work e-mail address, and work telephone number.

The organization, site, or location you belong to.

Your role and the permission level your organization has authorized for you.

Provided by your organization, not by you.

Create and maintain your account.

Provide the services your organization has contracted for.

Communicate with you about the service.

Authentication information

The one-time sign-in link we send to your work e-mail address when you log in.

The session token created on your device once you have signed in.

The App does not use passwords. We never ask you to create one and we do not store one.

Verify it is you signing in.

Keep your session secure.

Support and communication content

Messages, tickets, attachments, photographs, and other content you submit through the App or send to us.

Respond to your requests for support.

Deliver the services your organization has contracted for.

Website inquiry information

Name, e-mail address, address, and telephone number you choose to give us on our website.

Respond to your inquiry.

Login to the MyFlex App

 

Information we collect automatically through the App

Category of personal data

Examples

Flexible IT uses this data to:

Device information

Your device model, its operating system version, and its time zone.

Deliver the App correctly on your device.

Diagnose problems.

Identifiers

Your Flexible IT account identifier and a session identifier.

The App does not collect a device identifier, an advertising identifier, or any other identifier that could be used to recognize you across other companies’ apps or websites.

Connect your session to your account.

Keep the service secure.

Connection and usage information

IP address, sign-in and sign-out times, features used, and actions taken in the App.

Operate and secure the service.

Detect and prevent fraud and abuse.

Respond to requests for support.

Diagnostic information

Crash reports, error logs, and performance data.

Find and fix problems in the App.

 

Device permissions

With your permission, the App uses:

  • Camera, to photograph a device, error message, or on-site issue and attach it to a support ticket.
  • Photo library, to attach a screenshot or photo you have already taken to a support ticket.
  • Files, to attach documents, logs, or other files to a support ticket.
  • Notifications, to alert you to updates on your tickets and to service or security notices from Flexible IT.

The App does not request your location, your microphone, or your contacts. You can grant or revoke any permission at any time in your device settings; turning one off may limit the related feature.

Biometric unlock. If you choose to open the App with Face ID, Touch ID, or your device’s fingerprint or face unlock, that check is performed entirely by your device’s operating system. Your device tells the App only whether the check succeeded. Flexible IT never receives, sees, or stores your fingerprint, face scan, or any other biometric information, and biometric information is never transmitted to us.

 

Information we process on behalf of our clients

Flexible IT provides managed IT and security services to business clients. In delivering those services, and through the App, we access and process information belonging to those clients. For that information our client is the controller and Flexible IT acts as a processor or service provider: we process it only on the client’s documented instructions and in accordance with our Master Services Agreement and Data Processing Addendum, not under this Policy.

Category of personal data

Examples

Flexible IT uses this data to:

Client business records

Support tickets, device and network inventory, configuration data, endpoint records, and other business records belonging to the client.

Provide the services to the client on whose behalf we hold the information.

Respond to the client’s requests.

Other purposes permitted by our agreement with that client.

If you are an employee or end user of a Flexible IT client and you want to access, correct, or delete information held on that client’s behalf, please contact your own organization. We will refer your request to them and support them in responding.

Cookies and similar technologies

Our web server automatically creates log files for each visitor who accesses our site. These “access logs” allow us to make our site more useful to our visitors. The access logs do NOT record a visitor’s name, address, phone number, credit card numbers, or any other personally-identifying information. Rather, they contain some or all of the following information:

  • The IP address of the machine which accessed our website.
  • The date of the visit.
  • The time of the visit.
  • The pages visited on our website.
  • The browser being used.
  • A list of files downloaded or viewed.
  • Any errors encountered.

Our website uses cookies and similar browser storage. Some are session cookies deleted when you leave the site; others persist for up to two years. A consent tool manages them and records your choices. Our Cookie Declaration groups them into four categories: necessary cookies, which enable basic functions such as navigation, access to secure areas, caching and bot detection, and which the law allows us to set without your consent; statistics cookies, which show us how visitors use the site, including on-page behaviour recording and heatmaps; marketing cookies, set by advertising and analytics providers including Google and Microsoft, which track visitors across websites to make advertising more relevant; and unclassified cookies we are still categorising.

In the course of using our site we automatically track certain information about you, via log files, cookies, pixel tags and other technologies. This information includes the URL of the web page that you just came from (whether this URL is on our site or not), which URL you go to next (whether this URL is on our site or not), what browser you are using, your IP address, the number of times you visited Flexible IT website, which pages you visited and what materials, if any, you downloaded and location information.

Where you consent to statistics or marketing cookies, information about your use of our site is shared with those analytics and advertising partners, who may combine it with other information they already hold about you. Our Cookie Declaration lists every cookie we use, its provider, its purpose and how long it lasts, and you can change or withdraw your consent there at any time. You can also manage cookies through your browser settings, though blocking some may stop parts of the site working. The App does not use advertising or analytics cookies.

Lawful basis for processing personal information (EEA and UK only)

When we collect personal information from you in connection with offering our Website, Apps or Services within the European Economic Area (EEA) and the United Kingdom (UK), our lawful basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it.

We will normally collect personal information from you where we need the personal information to perform a contract with you (i.e. to provide the Services), or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may also have a legal obligation to collect the personal information in question  or we may process your personal information where we have your consent to do so.

If we ask you to provide personal information to comply with a legal requirement or enter into a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal information is mandatory or not (as well as of the possible consequences if you do not provide your personal information).

Similarly, if we collect and use your personal information in reliance on our or a third party’s legitimate interests and those interests are not already listed above (see the “Personal Information We Collect and Use” section), we will make clear to you at the relevant time what those legitimate interests are.

If you have questions about or need further information concerning the legal basis on which we collect and use your personal information, please contact us using the contact details provided under the “Contact Us” section below.

 

SHARING AND DISCLOSURE OF PERSONAL INFORMATION

We will not rent or sell your personal information, and we will not share it for cross-context behavioral advertising. We may share and disclose personal information that we collect (as identified in the “Personal Information We Collect and Use” section) with the following third parties, solely for legitimate business or legal purposes and in accordance with applicable law:

Service providers. We use third-party providers to operate the website and the App, in these categories: cloud hosting and infrastructure; identity and authentication; transactional e-mail delivery, which is how your one-time sign-in link reaches you; error and crash reporting; and customer support and ticketing. These providers may process your information only on our instructions, only to provide the service to us, and are bound by written agreements requiring them to protect it and prohibiting them from using it for their own purposes.

Legal and safety. We may disclose information where required for law enforcement or otherwise required by law, to respond to lawful requests and legal process, to enforce our agreements, or to protect the rights, property, or safety of Flexible IT, our clients, or the public.

Corporate transactions. We may disclose information to a third party in connection with an actual or prospective corporate transaction, a sale, merger, acquisition, joint venture, financing, reorganization, or insolvency. We will notify you before your information becomes subject to a materially different privacy policy.

With your consent. To other third parties where you have asked us to, or agreed that we may.

 

YOUR PRIVACY RIGHTS

Requests about information we hold for our clients

When we process information on behalf of a client as a processor, we do so on that client’s instructions. If you believe Flexible IT holds information about you on behalf of a client, or you want to access, review, correct, or delete it, you should contact that client directly. We will then help them fulfil your request in accordance with their instructions.

Rights over information we hold for ourselves

Where we process personal information as a controller, for our own account management, service operation, security, or marketing, you may ask us to do the following. We consider and handle all requests in accordance with applicable law, and we may need additional information to verify your identity.

Access. Ask what personal information we hold about you and receive a copy of it.

Correction. Ask us to correct or complete information that is inaccurate or incomplete.

Deletion. Ask us to erase personal information we hold about you. For your App account specifically, see “Deleting your account” below.

Objection. Tell us you object to our collection or use of your information for a particular purpose.

Portability. Ask for a copy of your information in a machine-readable format.

Withdrawal of consent. Change your mind about a consent you previously gave. This does not affect processing already carried out, and where we rely on a different lawful basis, a contract with you, or a legitimate interest of ours or of your employer, we may continue to process your information.

Additional Privacy Rights as a California Resident

If you are a California resident, or a resident of another state with a comprehensive privacy law, you may have the right to know the categories of personal information we have collected about you, the sources we collected it from, the business purpose for collecting it, and the categories of third parties we shared it with, as well as the specific pieces of information we hold. Flexible IT does not sell your personal information and does not share it for cross-context behavioral advertising. Our website uses advertising and analytics cookies, and you can withdraw your consent to them at any time from our Cookie Declaration. For any other privacy request, including access, correction, or deletion, submit a request through the form below. We will not discriminate against you for exercising any of these rights.

 

Deleting your account

Because Flexible IT creates accounts at the direction of your organization, your organization, not you individually, and not Flexible IT acting alone, decides whether your account continues to exist.

If your organization does not authorize deletion. We will tell you, and we will tell you who to contact at your organization. We cannot unilaterally delete records our client is required to keep. This does not affect any right you have under applicable privacy law to make a request directly to your organization, and we will support your organization in responding to you.

Data held for your organization. Deleting your account does not delete information we hold on behalf of your organization under its services agreement. Requests about that information go to your organization.

 

THIRD-PARTY SITES

Occasionally our website may contain links to other websites. Flexible IT is not responsible for the privacy practices or the content of those sites, and the inclusion of a link is not an endorsement. We encourage you to review the privacy statement of each website you visit before providing personal information to it.

TEXT MESSAGING
For details about how we handle information related to text messaging, please refer to our
SMS Terms of Use.

 

SECURITY

Flexible IT maintains an information security program designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. That program is independently examined: Flexible IT holds a SOC 2 Type II attestation, and a copy of the report is available to clients and prospective clients on request, under a non-disclosure agreement.

Our controls include:

  • Encryption of personal information in transit and encryption at rest for stored personal information.
  • Role-based access controls, so employees may access personal information only where their job requires it.
  • Multi-factor authentication for administrative and privileged access to systems holding personal information.
  • Logging and monitoring of access to systems containing personal information.
  • Background screening and periodic security awareness training for personnel with access to personal information.
  • A documented incident response process, including notification to affected individuals and regulators where required by law.

DATA RETENTION

We will retain your personal information for no longer than is necessary to fulfill the purposes for which the information was originally collected unless a longer retention period is required or permitted by law, for legal, tax or regulatory reasons, or other legitimate and lawful business purposes.

Where we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it.

CHILDREN’S PRIVACY

Flexible IT’s services are provided to businesses and are intended for adults. We do not knowingly provide products or services directly to children under the age of 16, and we do not knowingly collect or solicit personal information from or about them. If you believe a child under 16 has provided personal information to Flexible IT, please contact us using the form below and we will delete it.

UPDATES TO THIS POLICY

Flexible IT reserves the right to change this Policy at any time. Any changes will be posted to this page as soon as reasonably possible, so please check it periodically. Use of the Flexible IT website constitutes consent to the Policy then in effect. If we make non-material changes we will post them on this page and update the effective date above. If we make material changes we will tell you more directly for example by e-mail or by notice in the App before those changes take effect.

CONTACT US

If you have any questions, comments, or concerns about this Policy, or you wish to make a privacy request, contact us using the form below.

Flexible IT

290 Motor Parkway

Hauppauge, NY 11788